OTHER

Collaborative Real-Time AI Security: Engaging All Stakeholders, Google Included

I recently had the opportunity to discuss insights with Francis de Souza, COO of Google Cloud, in a backstage environment at an event in Los Angeles. Surrounded by a dynamic atmosphere, de Souza, who embodies the calm and thoughtful demeanor of a university professor, provided valuable insights for organizations navigating today’s AI security challenges, stating, “there’ll be a transition period, and then I think we get to this better place.”

In that moment, he wasn’t exclusively addressing Google, yet it was clear that even Google is experiencing uncertainties.

De Souza’s central message echoed a longstanding call from security experts for executives to recognize: security must never be an afterthought. “As businesses venture into their AI projects, they should adopt a platform-centric approach,” he asserted. “Security cannot be an add-on later, nor can it lie solely on the shoulders of employees.” He especially warned against “shadow AI,” where employees use consumer tools without company oversight, insisting that organizations need to enforce security, governance, and auditability right from the start. “There is no AI strategy without a data strategy and a security strategy; they must be intertwined.”

It’s crucial to note that he wasn’t just promoting Google Cloud. When I noted that his comments seemed to favor Google, he clarified. Google endorses a multicloud strategy, he argued, stating that companies believing they’re confined to a single cloud might be misinformed. “Even when entirely relying on one cloud, they use SaaS applications, and their business partners may be utilizing various clouds,” he explained. “It’s essential for organizations to uphold a consistent security posture across different clouds and models.”

He also highlighted that the evolving threat landscape has grown so intricate that traditional defense methods are becoming insufficient. He mentioned that the time from the initial breach to the actual attack has sharply reduced from eight hours to just 22 seconds, with the attack surface extending beyond typical network boundaries. “Outside your conventional environment, there are now models, data pipelines for training these models, agents, and prompts. All these elements require protection.”

One lesser-known threat de Souza emphasized involves agents navigating through a company’s internal systems, potentially uncovering forgotten data storage locations. “Many organizations still maintain outdated SharePoint servers and old access controls; it was never an issue before as their existence was overlooked. However, agents operating within your enterprise will expose those data assets and the information they hold.”

His proposed solution? Align machine speed with machine speed. “We are witnessing the emergence of an AI-native, fully agent-driven defense where companies can deploy agents to manage their security needs,” he explained. “Rather than relying solely on human-led defenses, you can have humans overseeing a fully agent-driven approach.” He emphasized that this issue has escalated to a leadership challenge, not just a technical one. “This topic is a priority for the board and executive team, not just the security department.”

However, as AI increasingly assumes security responsibilities, there is a lack of qualified personnel to supervise these processes — and the vulnerabilities introduced by AI are growing faster than security teams can manage. “We will need skilled professionals to tackle the bug-pocalypse,” stated Lea Kissner, LinkedIn’s chief information security officer, in a recent New York Times interview, asserting that it may take years for the industry to fully comprehend AI security.

This leads us back to platform providers. The Register recently reported on a spike in Google Cloud developers facing unexpected five-figure bills due to unauthorized API calls to Gemini models — services many hadn’t used or activated purposefully. These incidents followed a familiar trend: API keys, initially intended for Google Maps and made public as per Google’s own guidelines, had silently gained access to Gemini after Google expanded their usage without adequate notification.

Rod Danan, CEO of the interview-preparation platform Prentus, recounted receiving a bill of $10,138 within about 30 minutes after attackers compromised his API key. Similarly, Isuru Fonseka, a developer in Sydney, discovered charges nearing AUD $17,000 despite believing he had a $250 spending limit. Unbeknownst to them, Google’s automated systems had escalated their billing tiers based on account activity, raising their effective limits to as much as $100,000 without explicit consent.

Google refunded both individuals after The Register’s initial report. However, the company informed The Register that it does not plan to change its automatic tier-upgrade policy, prioritizing service outage prevention over user budget expectations.

Additionally, concerns arise regarding the protocol when a developer attempts to stop operations. The Register reported this week on findings from security firm Aikido, suggesting that even developers who swiftly delete a compromised key may still be at risk. Aikido’s research indicated that attackers could continue using that key for up to 23 minutes due to Google’s gradual key revocation process. Aikido researcher Joseph Leon explained to The Register that during this timeframe, success rates remain unpredictable — at certain moments, over 90% of requests still authenticate — allowing attackers to extract files and cached conversation data from Gemini.

Leon also noted that Google’s newer credential formats appear to mitigate this issue: service account API credentials revoke in about five seconds, and Gemini’s recent AQ-prefixed key format takes roughly a minute. “Both operate at Google scale,” he mentioned in Aikido’s related paper. “Both imply that this issue can technically be resolved for Google API keys as well.” Essentially, Leon asserts that the 23-minute delay isn’t a technical barrier but a matter of prioritization for the company.

This consideration is vital when reflecting on de Souza’s sage advice, which should be taken to heart. While he is accurate, there is a noticeable disconnection between the platforms’ recommendations and their own adaptation pace, a significant aspect to recognize as well.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.